Skip to content

fix: validate Azure delegation key coverage - #867

Open
RanaPriyansh wants to merge 1 commit into
apache:mainfrom
RanaPriyansh:fix/807-azure-delegation-validity
Open

RanaPriyansh wants to merge 1 commit into
apache:mainfrom
RanaPriyansh:fix/807-azure-delegation-validity

Conversation

@RanaPriyansh

Copy link
Copy Markdown

Summary

Azure can grant a user delegation key whose validity does not cover a requested signed URL. The fixed cache window can also fetch another key while a cached key still covers the signed URL.

This change makes the requested key validity configurable, with a 12-hour default. A longer signed URL extends the key request. The cache reuses a key only when Azure's returned SignedStart and SignedExpiry cover the serialized SAS interval. It rejects an invalid granted interval before caching the key.

Addresses #807.

Validation

  • cargo test --features azure --lib — 175 passed, four ignored.
  • cargo clippy --features azure -- -D warnings
  • cargo clippy --no-default-features --features azure-base -- -D warnings
  • cargo clippy --all-features --all-targets -- -D warnings
  • cargo fmt --all -- --check
  • git diff --check

Mock Azure responses test public signed URLs, cache reuse, refresh, concurrent signers, failed and canceled refresh, granted intervals, and the seven-day limit. The public tests compare SAS timestamps with the granted key interval and reject an insufficient grant. No live Azure account was used.

Codex used.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant